MFSA-RESERVE-2025-1958350: High severity thunderbird vulnerability
A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape.
Other sources
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape.
— Mozilla
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document’s process instead of the intended frame, potentially enabling a sandbox escape.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of MFSA-RESERVE-2025-1958350?
The severity of MFSA-RESERVE-2025-1958350 is high due to its potential for a sandbox escape.
How do I fix MFSA-RESERVE-2025-1958350?
To fix MFSA-RESERVE-2025-1958350, upgrade to the latest version of affected Mozilla products.
Which versions are affected by MFSA-RESERVE-2025-1958350?
Versions prior to Thunderbird 138, Firefox 138, and their ESR equivalents are affected by MFSA-RESERVE-2025-1958350.
What products are affected by MFSA-RESERVE-2025-1958350?
The affected products include Mozilla Thunderbird, Firefox, and their ESR versions.
What causes the vulnerability in MFSA-RESERVE-2025-1958350?
MFSA-RESERVE-2025-1958350 is caused by improper handling of javascript: URIs leading to process isolation issues.